# CVE-2026-84063

## Summary

- **CVE ID:** CVE-2026-84063
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-434
- **Published:** Sep 10, 2026
- **Last Modified:** Sep 10, 2026

## Description

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed may be caused.

## Affected Products

- D-ZERO CO.,LTD. — BurgerEditor (3.2.0 through 3.4.0)
- D-ZERO CO.,LTD. — BurgerEditor (2.28.0 through 2.30.0)

## References

- [CNA](https://jvn.jp/en/jp/JVN21088484/)
- [CNA](https://burger.d-zero.co.jp/blogs/archives/3)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.43%
- **EPSS Percentile:** 36.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._